SquidClamav URL Parsing Denial of Service Vulnerability
BID:54663
Info
SquidClamav URL Parsing Denial of Service Vulnerability
| Bugtraq ID: | 54663 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3501 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2012 12:00AM |
| Updated: | Sep 25 2012 03:40AM |
| Credit: | John Xue |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
SquidClamav URL Parsing Denial of Service Vulnerability
SquidClamav is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the daemon to crash, denying service to legitimate users.
SquidClamav versions prior to 5.8 and 6.7 are vulnerable.
SquidClamav is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the daemon to crash, denying service to legitimate users.
SquidClamav versions prior to 5.8 and 6.7 are vulnerable.
Exploit / POC
SquidClamav URL Parsing Denial of Service Vulnerability
Attackers must trick a victim into following a malicious URL to exploit this issue.
Attackers must trick a victim into following a malicious URL to exploit this issue.
Solution / Fix
SquidClamav URL Parsing Denial of Service Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
SquidClamav URL Parsing Denial of Service Vulnerability
References:
References: